Supply Chain Attack Compromises 143 Mastra npm Packages with Malicious Dependency
ID: 299455e9-7d2b-5f99-ae9a-8ebcb02b36aa
STIX ID: report--299455e9-7d2b-5f99-ae9a-8ebcb02b36aa
Feed Name: ThreatCluster
On June 17, 2026 an attacker hijacked a former maintainer account to republish 143 packages in the @mastra npm scope, injecting a malicious dependency called easy-day-js that masquerades as dayjs, disables TLS verification in a postinstall hook, and downloads a cryptocurrency stealer; widely used packages (including @mastra/core with ~4 million monthly downloads) were affected, and users who installed any affected packages after June 17 should consider systems compromised and remediate immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
